MyID + Entra ID + YubiKey
Issue, manage and revoke FIDO passkeys on YubiKeys through Microsoft Entra ID and MyID CMS. MyID CMS plugs into Entra ID's FIDO2 provisioning APIs to deliver full passkey lifecycle management and phishing-resistant, passwordless sign-in to Entra ID-protected apps, across cloud and hybrid environments. The same console also manages digital certificates, covering every credential on the key.
Enterprise FIDO passkey management with Entra ID
Intercede, Microsoft and Yubico have brought their platforms together so enterprises can issue and manage FIDO passkeys at scale. MyID CMS integrates with Microsoft Entra ID's FIDO2 provisioning APIs to register and lifecycle-manage passkeys on the YubiKey family for phishing-resistant sign-in to Entra ID-protected resources.
Passkeys, centrally issued
MyID CMS controls who is issued a passkey, on which YubiKey and under which policy. Each user enrols with their own physical key, while bulk tasks such as revocation run centrally, with every action authorised and recorded.
Phishing-resistant Entra sign-in
Passkeys authenticate users to Microsoft Entra ID-protected resources, delivering phishing-resistant, passwordless access.
Full passkey lifecycle
Every stage of the passkey's life, from issuance through expiry to revocation, managed centrally in MyID CMS with a full audit trail.
From issuance to sign-in
MyID CMS issues and manages the passkey; Microsoft Entra ID handles authentication.
Issue the passkey
MyID CMS registers a FIDO passkey on the user's YubiKey through Microsoft Entra ID's FIDO2 provisioning APIs.
Sign in, phishing-resistant
The user signs in to Entra ID-protected resources with the passkey for passwordless and phishing-resistant, in cloud or hybrid Entra ID.
Manage the lifecycle
Apply expiry policy and revoke passkeys centrally, including automatic revocation for leavers and fixed-term staff.
Why manage passkeys with MyID
Simplified issuance & lifecycle
Simplified passkey issuance and lifecycle management, self-service or operator-led on a user's behalf, from the same MyID CMS console that manages your digital certificates.
Expiry and automatic revocation
Issue long-lived and short-lived passkeys side by side, with expiry dates and automatic revocation. Ideal for fixed-term contractors and temporary devices.
One CMS, every Entra ID tenant
Works with cloud and hybrid Microsoft Entra ID deployments, with consistent registration, reporting and lifecycle processes across multiple connected tenants.
NIST SP 800-63B aligned
Issue and manage passkeys in line with the NIST SP 800-63B digital identity guidelines.
Passkey as a derived credential
Supports using a passkey as a derived credential, compliant with NIST SP 800-157.
Trusted YubiKey hardware
Manage passkeys on the YubiKey family of hardware security keys, backed by the Intercede, Microsoft and Yubico collaboration.
Operator-led issuance
Prepare devices ready for new starters, or let line managers and security teams issue temporary devices on a user's behalf. Strict policy controls and a full audit trail cover every action.
One passkey per person
Stop passkeys multiplying across your organisation. MyID CMS can limit each person to a single active passkey, so you always know exactly what every user holds.
Reuse YubiKeys, improve ROI
When a device is handed back, MyID CMS erases it and returns it to the pool ready to reissue. Your hardware investment keeps working.